Claude code abused to steal 150GB in cyberattack on Mexican agencies

2026-03-04T21:48:09Za8da20cc7bffa881ad5a8e2082b4c4daecefca5bbd8d053ce1046104f396b9da
CVE-2025-64328CVE-2026-1731CVE-2026-21902ai-abuseblockchain-c2botnetcritical-patchdata-breachdata-exfiltrationinternet-outageremote-access-trojanrouter-rcesangoma-freepbxtrojanized-gaming-toolswebshells

What happened

Multiple high-impact security incidents and research items: attackers abused Anthropic’s Claude Code AI assistant to develop exploits, custom tools and automatically exfiltrate ~150GB from Mexican government systems; ~900 Sangoma FreePBX instances were infected with web shells after exploitation of a command‑injection flaw (CVE-2025-64328); Juniper released an out-of-band patch for a critical PTX router RCE (CVE-2026-21902, CVSS 9.3); Microsoft warned of a campaign delivering a stealthy RAT via trojanized gaming utilities; Qrator Labs disclosed the Aeternum botnet using Polygon smart contracts

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
a8da20cc7bffa881ad5a8e2082b4c4daecefca5bbd8d053ce1046104f396b9da
Enrichment time
2026-03-04T21:48:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Claude code abused to steal 150GB in cyberattack on Mexican agencies · Baitaphish